Back to Articles
Govern AI Before it Governs You

The Australian

SKIPPED

Details

Date Published
16 Apr 2026
Priority Score
3
Australian
Yes
Created
27 July 2026, 04:00 pm

Authors (1)

Description

Many AI pilots are moving into production, productivity tools are spreading, and vendors are increasingly embedding generative and agentic AI across enterprise platforms. As this momentum continues, AI governance should evolve just as quickly.

Summary

This article outlines critical corporate governance frameworks for managing the transition from AI experimentation to full-scale enterprise production, with a specific focus on agentic systems with autonomous authority. It argues for a shift toward disciplined accountability and proportional risk tiering to mitigate operational and decision-making risks inherent in frontier AI capabilities. By emphasizing the need for boards to identify concentration risks and value dependencies, the author highlights how clear decision rights are essential to prevent AI failure from scaling into systemic enterprise risk.

Body

Govern AI before it governs youAs AI moves from pilots to production, boards should shift from technology curiosity to disciplined accountability, proportionate risk oversight, and measurable enterprise value.John MarcanteBoards are taking on a greater role in governing AIGift this article4 min read51 minutes agoMany AI pilots are moving into production, productivity tools are spreading, and vendors are increasingly embedding generative and agentic AI across enterprise platforms. As this momentum continues, AI governance should evolve just as quickly. For boards, the challenge is to maintain sufficient AI literacy to set strategic direction and effectively challenge management, while ensuring clear accountability, proportionate risk oversight and measurable enterprise value. AI governance should not be treated as a compliance checklist but as an operating discipline. A recent Deloitte Global survey finds that 66 per cent of C-suite and board members cite open, transparent communication between the board and management as the top factor influencing organisational resilience. Seventy-one per cent say strategic risk oversight and scenario planning are where boards can best help enhance organisational resilience. Nearly three-quarters (73 per cent) of survey respondents say their boards have stepped up their involvement in strategy development and scenario planning. As boards take on a greater role in governing AI, several priorities and structures should remain top of mind.Five AI governance priorities as organisations move beyond experimentationBased on my experience leading enterprise technology transformations and advising executives and boards, five governance priorities can help distinguish organisations building durable AI capabilities from those still experimenting.Govern AI as a portfolio of enterprise capabilities. Many organisations still track AI initiatives as an innovation activity. Boards should instead expect AI to be managed as a portfolio of investments, categorised by business impact, autonomy level, and risk exposure. This portfolio view may allow directors to identify concentration risk, value dependency, and operational reliance before AI becomes embedded in critical workflows.Separate model governance from decision accountability. Technical validation is necessary but often insufficient. The central governance question is ownership:• Who is accountable for decisions influenced by AI?• Who authorises deployment into production workflows?• Who monitors performance drifts?• Who has the authority to suspend the system when risk emerges?Without clear decision rights, AI risk likely becomes organisational risk.Treat third-party AI as enterprise exposure. AI capabilities are increasingly embedded in enterprise software, from finance and HR systems to cybersecurity and customer engagement tools. This extends AI governance beyond internally developed models. Boards should expect management to maintain visibility into vendor AI usage, data rights, model update controls, and audit provisions. Vendor AI risk is enterprise risk.Establish proportional risk tiering. Not all AI requires board-level visibility. Customer-facing AI, financial decision-making systems, and agentic systems with autonomous authority are likely to warrant higher scrutiny than internal productivity tools, for example. Risk tiering allows oversight to scale with impact rather than fear.Require measurable enterprise value.AI should appear in operating metrics, not just innovation briefings. Boards should expect reporting tied to cycle-time reduction, cost efficiency, revenue impact, or improved risk detection.Layers of a practical governance structureA practical AI governance structure consists of several layers, which together can help create clarity without slowing innovation. They include:• Board oversight. Defines strategy, risk appetite, and accountability.• Executive AI council. Prioritises investment and risk tiering.• Decision accountability. Assigns ownership for AI-related decisions across business, technology, and risk, including business outcomes, model performance, and controls.• Model and data governance. Establishes processes for validation and ongoing monitoring.• Infrastructure and third-party control. Ensures security and vendor discipline.The following questions, meanwhile, can help boards assess AI governance maturity:• Where is AI materially influencing enterprise decisions today?• Which systems operate with agentic authority?• What third-party AI exposure touches sensitive enterprise data?• How is AI-driven value measured and reported?• Who is accountable if an AI-enabled decision fails publicly?AI should not replace leadership. But it can help magnify the consequences of unclear accountability and weak governance. Organisations that capture value with AI will not necessarily be those running the most pilots. They will more likely be those that establish governance discipline early – before AI becomes inseparable from enterprise operations.John Marcante is former global CIO, Vanguard, and CIO-in-residence, Deloitte US CIO Program.As published in the 16 April 2026 edition of the WSJ CIO Journal. Disclaimer     This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional adviser. Deloitte shall not be responsible for any loss sustained by any person who relies on this publication. About Deloitte  Deloitte provides industry-leading audit, consulting, tax and advisory services to many of the world’s most admired brands, including nearly 90% of the Fortune 500® and more than 8,500 U.S.-based private companies. At Deloitte, we strive to live our purpose of making an impact that matters by creating trust and confidence in a more equitable society. We leverage our unique blend of business acumen, command of technology, and strategic technology alliances to advise our clients across industries as they build their future. Deloitte is proud to be part of the largest global professional services network serving our clients in the markets that are most important to them. Bringing more than 175 years of service, our network of member firms spans more than 150 countries and territories. Learn how Deloitte’s approximately 457,000 people worldwide connect for impact at www.deloitte.com. Copyright © 2025 Deloitte Development LLC. All rights reserved.  Read related topics:Artificial Intelligence